CVE-2014-1824: Code Injection
Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted Journal (aka .JNT) file, aka "Windows Journal Remote Code Execution Vulnerability."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1824?
The severity of CVE-2014-1824 is classified as critical due to the potential for remote code execution.
How do I fix CVE-2014-1824?
To fix CVE-2014-1824, apply the relevant security update provided by Microsoft for your affected version of Windows.
What are the affected versions by CVE-2014-1824?
CVE-2014-1824 affects Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2008 SP2, and others.
What type of attack does CVE-2014-1824 enable?
CVE-2014-1824 enables remote attackers to execute arbitrary code via a crafted Journal file.
Is there a workaround for CVE-2014-1824 if I can't update?
A recommended workaround for CVE-2014-1824 is to disable Windows Journal or avoid opening untrusted Journal files.